Workforce identity
People get productive. Access stays precise.
Unify employees and contractors with passwordless SSO, adaptive MFA and automated joiner-mover-leaver workflows.
A FluxCore identity platform
From employees and customers to devices and AI agents, StratoID puts access, governance and endpoint trust in one sovereign control plane.
Labelled browser fixtures · No provider or device writes · Not GA
IDENTITY IS THE CONTROL PLANE
StratoID follows trust across the full lifecycle—before sign-in, during access and after the session ends.
Workforce identity
Unify employees and contractors with passwordless SSO, adaptive MFA and automated joiner-mover-leaver workflows.
Customer & partner identity
Create branded tenant realms, inbound enterprise federation, secure registration and privacy-aware account controls.
Device identity
Bind access to enrolled laptops, phones, Wi-Fi, VPN and Linux devices with posture signals that follow every decision.
Non-human identity
Issue tenant-aware machine credentials with narrow scopes, short lifetimes and no standing refresh access.
THE STRATOID PLATFORM
Secure employees, contractors, devices, applications and networks with one context-aware policy plane.
Give customers, partners, AI agents and service clients secure access without sacrificing speed or brand control.
106 ADVERTISED OPERATIONS
Explore 16 interactive capability domains. Their release states vary; the public demo is not production evidence.
Multi-tenant provisioning, user directory, group membership.
Token issuance, refresh/revoke, registration, password reset, device sessions, service clients.
A hosted LDAP directory — no VM, no patching, no FreeIPA ops burden.
Cloud RADIUS for Wi-Fi and VPN — NAS clients, MFA-gated authorization.
SAML + OIDC app catalog — metadata, assertions, one identity for every app.
TOTP enrollment/activation, verification, backup codes, factor management.
Password strength, conditional access (Zero Trust), local-account / sudo mapping.
Reference device workflows across five platforms — real OS management remains externally blocked.
FileVault, BitLocker, Wi-Fi, passcode, USB-restriction — assigned by group, device or platform.
External storage / AirDrop / personal-cloud controls, authorized drives, event stream.
Per-user SSH key management, projected as authorized_keys for enrolled Linux devices.
OS + third-party patch policies, catalog, per-device status, one-click remediation.
Simulated Google, M365, AWS, Git and Kubernetes connector records; live reconciliation is not released.
Entitlement catalog, time-bound access, independent approvals, revocation and certification evidence.
Safe metadata-only repository analysis, software identity, SBOM/signing evidence and readiness scoring.
Natural-language plans with exact actions, dry runs, approvals, rollback and tenant-scoped audit evidence.
SEE THE CONTROL PLANE
Follow how StratoID combines lifecycle, authentication, device posture and audit evidence instead of handing them to disconnected tools.
Lifecycle automation
Explore an illustrative leaver sequence; downstream provider deprovisioning is simulated in this demo.
Open user lifecycleOUTCOMES, NOT OVERHEAD
One neutral, extensible control plane for the teams that operate, secure and build your digital estate.
Replace fragmented directory, SSO, RADIUS and endpoint tooling with one operating plane.
Explore the solution 02Continuously evaluate identity, device, network and risk before access is allowed.
Explore the solution 03Ship OIDC, OAuth 2.1, SAML, SCIM and machine identity without an identity detour.
Explore the solution 04Turn HR events into automatic provisioning, entitlement changes and fast deactivation.
Explore the solutionEXTENSIBLE BY DESIGN
Synchronise directories, provision downstream applications and enforce the same trust decision across cloud and network infrastructure.
Explore simulated integrationscurl -X POST \
https://id.example.ng/oauth/token \
-d grant_type=client_credentials \
-d scope="directory:read devices:read"
# 15-minute, tenant-scoped token
{
"token_type": "Bearer",
"expires_in": 900
}BUILT FOR BUILDERS
Connect applications, automate operations and issue machine credentials through familiar protocols and tenant-scoped APIs.
ENGINEERED AS A CONTROL PLANE
StratoID makes its critical identity-path objectives explicit, so availability, revocation and auditability can be designed and verified.
PRODUCTION BOUNDARY DESIGN
Authentik is the selected production issuer; deployment and conformance evidence is pending.
SpiceDB adapters and deny-by-default checks are implemented; deployed tuple evidence is pending.
Vault Transit adapters protect server-held sessions and audit signatures when real infrastructure is supplied.
Durable audit/outbox code exists; SIEM export, recovery and operational evidence remain blockers.
RELEASE STATUS · NO-GO FOR GA
Connectors, real OS management, signed mobile releases, the network data plane, multi-region recovery, load, accessibility and independent security evidence remain blocked. Capability states and owners are tracked in the repository.
Read current limitationsREAD. EXPLORE. BUILD.
Trace a leaver event from session revocation through SaaS suspension, endpoint lock and evidence capture.
Explore now INTERACTIVE LABChange identity, endpoint, network and risk context to understand exactly why access is allowed or denied.
Explore now DEVELOPER STARTERConfigure standards-based SSO or create a tenant-scoped M2M client in the working StratoID console.
Explore nowREADY WHEN YOU ARE
Explore the reference workflows, evidence boundaries and current capability states.